CVE-2026-40369High· 7.8▾ MidnightPoC availableHeap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 42.9 · likelihood 0.9 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.7%
6 GitHub repos
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-62737High· 7.8Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-21338High· 7.8Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-35250High· 7.8Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2024-30090High· 7.0Microsoft Streaming Service Elevation of Privilege Vulnerability
CVE-2026-94403High· 8.8A weakness has been identified in ColorFul iGameCenter 1.0.3.4
CVE-2026-82927Medium· 5.5Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e.